skill-evolution

Fail

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/analyze-skill.sh is vulnerable to shell and SQL injection. The variable $SKILL_ID is interpolated directly into a double-quoted string passed to the sqlite3 CLI ("SELECT COUNT(*) FROM skill_metrics WHERE skill_id='$SKILL_ID';"). An attacker providing a malicious skill ID could execute arbitrary shell commands via subshells (e.g., $(rm -rf /)) or manipulate the database through SQL injection (e.g., '; DROP TABLE skill_metrics; --).
  • [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface through its automated analysis and evolution logic.
  • Ingestion points: External data enters the agent's context through {project_path} and {feedback} in prompts/post-execution.md, and {trigger_reason} in prompts/evolution.md.
  • Boundary markers: The templates lack boundary markers or explicit instructions to treat variables as untrusted data, allowing embedded instructions in project files or feedback to influence agent behavior.
  • Capability inventory: The skill possesses capabilities to modify the local filesystem (writing to monitor.md and evolution-log.md) and manipulate the internal database used to drive agent evolution decisions.
  • Sanitization: No sanitization, validation, or escaping of ingested strings is performed before they are interpolated into prompts or script arguments.
  • [COMMAND_EXECUTION]: The script scripts/report.sh programmatically generates monitor.md. If a skill name or metric in the database is compromised via the aforementioned SQL injection, it can be used to inject malicious markdown content (such as deceptive links or instructions) into the monitoring dashboard, which is then served to the user or agent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — skill-evolution